Skip to content

Discuss whether Cve-Services should enforce/validate affected versions #1135

@jdaigneau5

Description

@jdaigneau5

Summary

Affected versions in the 5.0 schema follow a semantic versioning pattern, which could be validated by Cve-Services, but currently is not because it's an optional field. However, this allows invalid semantic versions to be submitted in CVE records.

Definition of Done

  • Discuss whether Cve-Services should validate and enforce affected version field

Note
This is related to an overall discussion about whether optional fields should be validated by Cve-Services at all or not.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Needs Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions